Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 12th February 2020

PassW0rd – 12th February 2020

Play

Speaker A: This program is brought to you by Resonance 104.4 FM.

Speaker B: If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm. Hello and welcome to Future Intelligence’s Parsha on Resonance FM, a monthly overview of what’s happening in the world’s biggest industry, technology. This month we’re looking into the Chinese telecoms company Huawei and exactly why such a furious row has broken out over the company’s presence in the UK’s internet and telecommunications backbone. It’s a fascinating story of government and intelligence agency intrigue, political incompetence, and skullduggery that has all of the ingredients of a spy novel. There’s commercial espionage, a trade war, an intelligence agency turf war, the threat of an information war, and all set against a battle for the technology of the future. The 5G network that will apparently run our smart cities and automated vehicles. Who could want for more? So let’s do a bit of scene setting to begin with and give you a little history on Huawei, a company that in the 32 years since its founding in 1988 has become a global telecommunications giant with revenues of over $100 billion $122 billion and a somewhat shady reputation according to its many detractors. The French novelist Balzac commented that behind every great fortune there was a great crime, and for those who are attacking the Chinese company, they claim that this is most definitely the case. MFC Insight was a joint Sino-Australian industry research company that provided BT with business intelligence as part of BT’s due diligence in 2002. At the time, BT was considering asking Huawei to bid to provide equipment for what was then known as a 21st century network and needed to know more about the company. Here’s an extract from the MFC Insight report into Huawei under a section called Strong R&D.

Speaker A: Huawei’s approach was very similar to the formula used by the Japanese in the 1960s and the Koreans in the 1970s. Steal technology at first, re-engineer the technology so as to learn how to, then sink significant amounts of money into the original R&D to keep up with the competition. Huawei now reinvests at least 10% of its revenue back into R&D each year and maintains an extensive domestic research base. Initially, Huawei acted as a seller of imported telecom equipment. It also created a small cadre of researchers who reverse-engineered imported switching devices and network equipment to produce Huawei’s own branded versions. When developing the market or acquiring market share, Huawei often adopts an aggressive sales strategy. Usually, Huawei’s marketing and sales costs are relatively lower than that of other vendors. However, the company doesn’t fear extra costs if product sales can help Huawei increase market share. In other words, Huawei is willing to buy market share, including offering giveaways. The company also likes to use its political connections whenever suitable.

Speaker B: Essentially, MFC were warning BT that Huawei was in the business of intellectual property theft and that it had used it as a technique to grow its business. It would not have been a message that would have been lost on Brian Shields, a cybersecurity expert who became a whistleblower when he worked for the Canadian communications company Nortel. Nortel was a huge company with a huge range of competence. It provided equipment right across the board and was an industry leader. While working for them, Shields was puzzled by a string of intrusions in the company’s computers and started to investigate, and was shocked to discover a trail of hacked senior management computers he claimed led to China. But when he told Nortel chiefs, they refused to listen, so Shields went public. Here’s an interview we did with him in June 2019.

Speaker D: They were basically going in and logging in, and they were taking the whole contents of a folder, whatever that folder was. It was like a vacuum cleaner approach. They weren’t just picking and choosing, they were just taking everything.

Speaker B: Okay, so how much data did they get, do you think? Do you know what quantities of documents they were? Whether this was, you know, presumably this is gigabyte plus, isn’t it?

Speaker D: Oh, I— the size, yeah, I don’t know. I couldn’t— I can’t tell you today. I don’t recall. But I will tell you this, that in— just in the 6 months that when we discovered this in 2004, it was over 1,500 documents. So if you translate that, you know, it could be plus or minus hundreds or, you know, 500 or a couple, you know, whatever. And that went all the way back to at least the year 2000. So they basically had whatever they wanted. There was nothing they couldn’t get at because I’m sure that they had the CEO’s password, for goodness sake. Now, this data went to China.

Speaker B: You don’t know that it went to Huawei. Presumably it went to Chinese intelligence, if it did go to China.

Speaker D: Yeah, I absolutely— I have never come right out and said that, you know, Huawei was doing the stealing. I don’t believe that. Actually, I do believe 99.99%, you know, 100% essentially, the Chinese government that was behind this. This was an advanced attack. They were well hidden. We didn’t find them. They knew how to do all these advanced things to be able to get access to whatever they wanted and not be detected. And this went on for at least 10 years. So considering that, you know, most companies, you know, they eventually figure this stuff out. We didn’t figure it out. It happened to be because of a guy looking at a log file. The only reason we figured this out. Otherwise, I don’t think we ever would have noticed. This doesn’t happen because somebody’s an amateur. This is because somebody’s very advanced. And the fact that it was going— here’s the other thing. Half of the downloads were going over to Shanghai, all right? The company, the ISP was listed as Faccian Corporation, their base. This was listed as Shanghai. And I’m like, well, geez, that’s where unit 61398, the APT-1 that the Mandiant at the time, now FireEye, You know, their report came out and talked about, you know, as an advanced attack team that’s based over there in China, in Shanghai coincidentally. So is this a coincidence that, you know, most of our data was going over to Shanghai? And one of the things that I saw, and people aren’t aware of this, is that network that was being used, I am absolutely certain that entire address space, it was one whole net. I don’t want to get too technical here, but basically address 1 all the way up to 255 are all allocated. Instead of being ISP that, you know, like your users at home could log in and use this, I saw things that consistently looked organized, structured, and like they— it was beyond random, which it should have been, like if I was logging in from home. So one of the things that gave me a clue to find these guys in our network and try and stay on their trail was that they stopped for 6 months. And yet this is an ISP over in China. Well, why would this stop? It shouldn’t have stopped if our employees are still working from home. And that’s why I knew they were still on our network. And I couldn’t get any help. This is the thing, my frustration that I mentioned to you earlier on. You know, you go to management, and I actually go to the telecom team and say, hey, look, I need you guys to sniff this traffic because I want to see what it is. I want to look at it. I want to see if I can read it. Or is it encoded? And it took me almost 3 years to get them to finally set up where I can get packet captures. I mean, this is ridiculous. Here you’ve got an advanced compromise and I’m getting no help. I can’t even get, you know, it’s like I’m all on my own.

Speaker B: That was the Nortel whistleblower Brian Shields, who in an email to me added that cutthroat pricing was definitely part of the way Huawei won in the market. It’s not too hard to see why Nortel failed if you consider you have a competitor that is not just underbidding you, but the underbidding is meant for you to always lose, which ultimately leads to your total and complete demise. Cutthroat pricing is what ultimately resulted in Nortel’s failure. Cutthroat pricing that Shields says that Huawei could succeed in because they had obtained commercial information on the bids that Nortel were making because hackers working for the People’s Liberation Army Unit 61398 in Pudong, Shanghai were taking it from the computers of Nortel executives and passing it to Huawei. A report by the US computer security firm Mandiant, rumoured itself to have strong links to US intelligence, stated that PLA Unit 61398 is part of the PLA’s General and is responsible for economic espionage. Nortel went spectacularly bust. Intriguingly, the only company in the world that was able to offer the same range of communications services as Nortel was Huawei. This is Henning Schultzrinne, the former chief technology officer for the US’s Federal Communications Commission.

Speaker C: To some extent, Huawei has a much broader product portfolio as compared to Nokia and Ericsson as, let’s say, the infrastructure competitors. They really, as far as I can tell, the only supplier that has pretty much a presence across the networking realm. So they build enterprise equipment, they have radio equipment or radio infrastructure. They have routers, they have handsets. If you look at Ericsson and Nokia, for example, they really don’t. They have mobile network infrastructure. They don’t have routers, they don’t have handsets, they don’t have enterprise equipment really of any significance, and so on. So when one compares research expenditures between those, one has to take into account how we both have an advantage and a disadvantage. The advantage is is they’re much more like what to some extent was the case for somebody like— if you think of the closest historical analog, it would be somebody like Nortel, a very large company that pretty much covered everything from telephone switches to radio equipment to enterprise equipment. Those don’t exist in the non-Chinese universe anymore.

Speaker B: Lucent, who Schultz-Rin mentioned there, is considered to have also had a brush with Huawei. Employees at Lucent are now part of a resurgent Nokia that has dispensed with its mobile phones and now makes the backbone the mobiles send their signals across. Some of those we spoke to claim that Lucent’s DSLAM switch hardware and software has been completely copied by Huawei. A massive irony because of the controversy that has started over Huawei’s presence in the proposed UK 5G networks because it is now beginning to revolve around the installation of Huawei equipment in the masts. As a result of the mudslinging over intellectual property and data theft, Huawei’s critics are claiming that it cannot be allowed to be in the UK’s network because it has proved that it is not trustworthy. They also point to Huawei’s close ties to the Chinese government and the military, both issues raised in a briefing paper prepared for BT by MFC Insight in 2002.

Speaker A: Huawei was founded in 1988 by Ren Zhengfei, a former director of the PLA General Staff Department’s Information Engineering Academy. Which is responsible for telecoms research for the Chinese military. Ren left the academy in 1984, aged 39, and went to work for the state-owned Shenzhen Electronics Corp. 4 years later, with a loan of $8.5 million from a state bank, he founded Huawei with the help of 14 army colleagues and remains the president of Huawei. Ren Zhengfei’s military background greatly affects his management style and Huawei’s company culture. Ren Zhengfei was the core of the company during the company’s development, and now no one else can surpass him. Ren personally holds 20-30% of Huawei’s stake, which strongly supports his authority in the company. Working at Huawei is more like working in the military than working in a company. In comparison with other companies, Huawei has a stricter atmosphere. Staff are required to show respect to Ren Zhengfei, which has led to a high rate of staff turnover. It remains questionable whether the money paid to outside consultants will change Huawei into a company with methodical management systems. Ren Zhengfei plays the most important role in Huawei and makes the final decisions for the company. In the early 1990s, Huawei received a contract to provide key equipment for the PLA’s first national telecoms network, which it continues to supply and upgrade. Although the PLA telecom project was small in terms of Huawei’s overall business, it was a keystone of the growing relationship between Huawei and the military. Later, the PLA was desperately in search of better information technology equipment that would help to build a modern military. Huawei became the vehicle used by the PLA to reach that goal. The turning point for Huawei came in 1996. That year, Beijing introduced an explicit policy in support of domestic telecoms companies in a bid to prevent foreign domination of Chinese equipment industry. Both the government and the military began to tout Huawei as a national source of pride. In November 1996, Liu Haikuan, Vice President of the Central Military Commission, took time out from an inspection of PLA troops in Shenzhen to visit Huawei’s headquarters.

Speaker B: According to the highly respected China watcher Isabel Hilton, Huawei and the Chinese military and the Chinese state are inextricably linked.

Speaker E: When you say run by the state, I would just calibrate that slightly because a lot of these begin as nominally private companies, but the fact is that in China you cannot thrive, particularly in the telecom sector, without the approval of the Party and without collaborating with the Party. So you simply wouldn’t get anywhere. So that although companies such as Huawei say, “We are a private company,” The fact is, you know, they would be shut down if they refused to collaborate with the party state or with the intelligence services. And there is legislation to that effect in China, you know, mandating the cooperation of any Chinese entity with the intelligence services. So it’s, it’s a thin fiction. And these, these companies have been encouraged to get as large as they have grown by a series of state measures which effectively screened them from international competition, which subsidized them, which gave them sweetheart deals in terms of land for their factories or installations, in terms of loans from the state-owned enterprises, and so on. So although they would argue, and they do argue, that they’re not actually run by the state, it’s part of a range of measures that the party-state uses to exert control over them. They claim that we’re just owned by our workers, just like John Lewis, and actually if you try to examine, you know, what does that mean and how are decisions taken and, you know, what is the actual structure, you hit a bit of a wall quite quickly. So, you know, you’d have to be pretty naive to imagine that Huawei was not, you know, joined at the hip with the party state.

Speaker B: For the US in particular, this is the issue. Huawei, which means Chinese achievement, is not only Chinese, it is proof that the US is falling behind in the most fundamental part of the tech infrastructure, the bedrock system that receives and transmits the data demands from our phones and other devices, and will also receive the instructions and data that will allow the building of the smart cities of the future. It’s a fear US President Donald Trump summed up in a tweet at 2:35 PM on February 21st, 2013. China is not our friend. They are not our ally. They want to overtake us, and if we don’t get smart and tough Soon they will. Because of this, there is much talk of regaining control of national infrastructure. In the US on February 6th, President Trump’s Attorney General William Barr said that the United States and its allies should consider the highly unusual step of taking a controlling stake in Finland’s Nokia and Sweden’s Ericsson to counter Huawei’s dominance in next-generation 5G wireless technology.. While in the UK, Labour politicians stated that we should now begin to subsidise a UK telecoms industry alternative to Huawei, an initiative laden with irony given the demise of the UK telecoms company Marconi in its bidding war against Huawei for the BT contract because of the then Labour government’s unwillingness to underwrite the £500 million extra that it would have cost to have had a UK company running the network. In a further twist, one of the reasons given at the time was that European competition rules would not have allowed the UK to back Marconi, a redundant argument according to Professor Andrew Jones, a military and cyber expert.

Speaker F: We don’t have a choice, we’ve got to be internationalists. The internet isn’t a UK-based thing, it’s a global thing. You know, the Russians are looking at developing their own infrastructure. The Chinese are. But the reality is, if we want to be part of a global community, it has to be a global thing. I cannot see a way forward for a UK splinter, if you like.

Speaker B: But the— I mean, the Chinese seem to be quite long-sighted in this. They’ve copied every single bit of the internet infrastructure. They’ve got their own search engines, they’ve got their own auction sites, they’ve got their own social media, everything that we’ve got, they’ve got in China.

Speaker G: Yep.

Speaker B: So they seem to think that you can have a dedicated internet that’s all your own.

Speaker F: They have a slightly larger population, which makes it realistically more viable. Also, the internet is primarily at the moment an English language vehicle, so it’s understandable why Somewhere like China would perhaps want to have those sort of things in their own language, given the Chinese philosophy, government philosophy as well. They also want control of it. So all of that’s very understandable. But would it work for us? I don’t think so. We just ain’t a big enough player.

Speaker B: Okay, so some people have said that if the government wants to build or wanted to build security, i.e., that sort of same domestic security into the internet that everybody’s complaining we don’t currently possess, that at the time of commissioning the 21st Century Network, they would have had to have spent twice as much. It’s going to be a lot more than that now, isn’t it?

Speaker F: Yes, orders of magnitude more. 21st Century Network was a number of years ago, and the world has moved on significantly since then, and so has, if you like, the internet, when the state of the internet at the moment was far beyond the imagination of the people who created 21st Century Network.

Speaker B: So it has been suggested that one of the reasons that was given for the government not wanting to support British businesses was that European Union regulations on competition EU didn’t allow it to, so you couldn’t have a national champion in the way that the Chinese have a national champion.

Speaker F: It’s when it involves national security that trumps EU. So it would have been— if the will had been there, I’m sure it would have been achievable.

Speaker B: So we have the option of either resurrecting a company to be the equivalent of Marconi or of trying to work a situation which Donald Trump says he’s not very happy with. He says that he doesn’t wish to share information with us because we can’t be trusted, because we’ve got somebody inside our network.

Speaker F: We’ve heard this from the Americans before. I might point out that most of the major leaks have been through the US rather than through UK. Or any of the other partners. So you might say, put your house in order before you shout.

Speaker B: But it is economic concerns that Dr. Tim Stevens, a senior lecturer in global security at the Department of War Studies at King’s College London, lies behind the US’s belligerent position towards Huawei.

Speaker I: If you go back to the conversations earlier in 2019 about Huawei at the cabinet level, it was very noticeable that the people that were most vociferously opposed to Huawei were in fact the Tory leadership challengers, which might tell you something a little bit about what this is being used for in political terms. Um, it also tended to be the people who were most vociferously pro-Brexit. So there’s clearly something going on in there, and it sounds to me much like, well, we’re going to be against China because the Americans are being against China, rather than actually some more considered reflection upon what the actual risks and threats are in this space. Now, it’s not as if senior Tories in government, or indeed cabinet, have not been briefed by national security officials on this issue. It’s that they don’t want to take the advice of their own intelligence community, or at least GCHQ. And this is very similar, in fact, to what President Trump said when he came into power, that he wasn’t going to take the advice of his intelligence community either. So there are some interesting political similarities between what’s happening at cabinet level in both Washington and London.

Speaker B: The example in Washington would seem to indicate that Donald Trump wanted to push for a trade dispute that he could get some— to use a word that I’m not in favor of— leverage Or because it wasn’t— there was not an American company that would have been a beneficiary. So his argument that Huawei was a security risk to the US doesn’t hold water because most of the other companies who have competency in that area are also foreign companies.

Speaker I: They are, yes, but you would probably rather do business with Scandinavian companies than you would Chinese. And this, this is This is— I don’t see any of this as being a technical issue. This is all politics. And in terms of the decision around Huawei, and, you know, the decision was really made an awful long time ago when we decided we were going to use Huawei kit in the first place. It’s not as if people didn’t spend the 2000s speaking out from the intelligence community about the cyber threat from China. They did. But we put in Huawei kit anyway, going back right to the early 2000s, and we’ve been living with it ever since. And it’s right, there is no obvious replacement for that now. We’re in a sense, we’re kind of a long way down a path that’s been set out for us an awful long time ago and trying to find a way out of it. Interesting thing from the American perspective is that the Americans, particular elements within Congress, have been vehemently opposed to any sort of Chinese involvement in anything for a very, very long time. And have really, really found their voice over the last couple of years. And they tend to be very right-wing, they tend to be quite protectionist, and their voice is now being heard. But the question is, you know, I think the issue around Huawei is essentially we don’t want to do business with the Chinese. We’d rather have a trade war, or at least a conflict in which we can somehow extract some concessions that are good for the American national national interest. And the UK has been very happy to play along with that, to a large extent, which is why the decision that the Boris Johnson government has made is actually quite a brave one. It’s not necessarily what I expected them to do. And it’s not what a lot of commentators, other commentators expected them to do. But I think in a way, we’ve been, the UK has been put in a very unenviable political situation. It’s been told you have to choose us, the Americans, or we’ll turn off intelligence, or you choose the Chinese and join the dark side. The problem with that is that we’ve been courting Chinese direct investment for so long now that we’ve— it’s very difficult to reverse that process.

Speaker B: Ironic, isn’t it? Because this has been political expedience all of the way. Because Tony Blair wanted to have a 21st century network. And at the time, Sir Christopher Blanche said to him, Are you going to pay for the security implications of having Huawei in as quickly as possible and as cheaply as possible? And the government said no.

Speaker I: Yeah, I mean, there’s a lot to be said for reexamining recent history around this, and it’s not— for those of us who’ve been looking on at this discussion for, you know, well over 10 years now, And there’s people within the decision-making bodies of UK government and Whitehall that have been looking at it for much longer. None of this is a surprise. It’s been political at every step of the way, and it’s been about economics. It’s been about what can we get rolled out quickly. And the thing about Huawei is that the British government, a Conservative government, promised the British people high-speed mobile broadband. And now that’s, that was a manifesto promise. It was a policy decision, and now they have to deliver on it. So they’ve been looking for a way of delivering on it while keeping Americans happy and keeping the Chinese happy. And the decision they’ve come to is actually probably a pretty smart decision given that political situation. I’d say it’s not ideal. I think most of us would agree that in an ideal world, Huawei would not be supplying 5G infrastructure to the United Kingdom.

Speaker B: But it’s not just the US that wants Huawei out of the UK network. MI5 too can’t wait to see the back of the Chinese giant. Here’s King’s College’s Dr. Stevens again.

Speaker I: It does seem to be something like that behind the scenes for sure. Certain current and former members of the intelligence agencies have come out on one side of the debate or another And GCHQ, including through its— through the National Cyber Security Centre, has come down firmly on the side of established policy, which is to be able to risk manage Huawei through various means. Whereas on the MI5 side, it’s definitely the implication that should we do this, should— then we’re allowing Huawei in, not just through the back door as we’ve heard until now, or as Mike Pompeo is saying today, is through the front door as well.

Speaker B: You know, let’s be clear about this. GCHQ say they can manage this. They say that their role is about the confidentiality of information. They’re pretty clear that they can, that they can do that, whereas MI5 seem to be saying, no, this isn’t about the confidentiality about, of information, this is about availability. They could turn us off.

Speaker I: Yes, that’s the argument in a nutshell. Yeah. The implication being there that Huawei will be leveraged by the Chinese state to, for example, just simply turn off the 5G network in the UK. One has to temper that a little bit with wondering under what circumstances would the Chinese ever do that. I think we would have to be fairly advanced in a crisis already for that type of event to take place. So I think we, we have to consider that such measures have not yet been undertaken by any state really in a prolonged sense against any others, and certainly not the Chinese against the US or any one of its allies. So it’s, it’s, it’s speculative. It’s not an unreal threat, as it were, but it’s certainly a very, very distant one.

Speaker B: Well, some of the people I’ve spoken to have mentioned Estonia. They said, look, there’s an example of a state being turned off by an unfriendly power. The Russians turned them off because they were in dispute with them about ethnic Russians living in Estonia grouping around the statue.

Speaker I: Well, indeed, but it wasn’t the Russian state that actually did that. It was proxies who had been given a nod and a wink, perhaps, to, to be able to do that. Now, you could argue that Huawei in that case would be acting as a proxy of China, and that would be a valid argument. But my point is that that was 2007. Yes, Estonia was a member of NATO, but the UK is a different breed, is a different creature. It’s much more closely aligned with the United States. It’s a part of the Five Eyes intelligence arrangement, which Estonia is not. And a blow to the UK of that nature would be a very severe one indeed, and, and a significant escalation were it to come out of the blue of a crisis that currently doesn’t exist.

Speaker B: Well, I’ve just been talking to a a US expert on intelligence committees, sat on a number of intelligence committees. He said that the risk is that you haven’t got any certainty that you’ve got an organization that is involved in your critical national infrastructure which isn’t part of your team. That, you know, if this were a cybersecurity incident and you knew you’ve got a hacker inside your network you wouldn’t be able to trust any of your data. And that’s basically what Mike Pompeo is saying.

Speaker I: Yeah, but Huawei isn’t arriving in our national infrastructure overnight. It’s been in national infrastructure since the 2000s. China has had ample opportunity during that time to switch the lights off in this, in this hypothetical scenario, has chosen not to take it. My point is, why would China decide to do that out of the blue unless there were already a crisis escalating. There is no escalating crisis here. So, I mean, if it were hypothetically possible, and who knows whether it is or not, then so be it. But we are not anywhere near a crisis with China at the moment. Now, okay, so something’s going to happen, you know, events, dear boy, events. And it may be in the future, you know, 10, 15 years’ time. But actually, the way that the UK government has presented this is almost as a way of squeezing Huawei out, or at least of the core of the networks. And in that sense, it’s a much more future-looking proposition than the Americans seem to give it credit.

Speaker B: So this is politics at an international level and at an intelligence level, and everyone seems to have some stake in the game. The US want to demonize Huawei as part of a trade war Conservative UK Brexiteer politicians like Sir Ian Duncan Smith want Huawei out of the UK’s network, and GCHQ and MI5 are at cross purposes over this, with MI5 accused of briefing against Huawei and GCHQ saying it is confident it can manage the risk. A stance that some have said is based on more than just an argument over policy, because GCHQ gets equipment, money, expertise, and the responsibility for cyber from its position monitoring the Huawei equipment in its Huawei Cybersecurity Evaluation Centre, a responsibility many observers say that MI5 is jealous about. This war of cloak and dagger has seen some frantic transatlantic lobbying with US State Secretary Mike Pompeo trying to convince the UK to drop Huawei from its 5G plans, a task he was joined in by Rob Joyce, a former National Security Agency officer and a top American cybersecurity official who served as special assistant to President Trump and was his cybersecurity coordinator on the US National Security Council. He was recently spotted in London. You are listening to Password on Resonance FM with me, Peter Warren. After this, you can hear A World in London with DJ Ritu. And here on Password, we are talking about the controversy surrounding Huawei. According to Password sources, the anti-Huawei message from the US contained no substantive new reasons for an abrupt to change to the UK plans. One insider told us, “It’s the same thing that they’ve been saying since 2009. There’s nothing new,” and dismissed the threats to withhold sensitive information as counterproductive, saying, “It’s not like Europol where you are worried about giving intelligence to some states because it might make its way back to the people it is about. The US need to give us intelligence and receive it back.” And there are channels that exist already to do that, and they do not need to involve Huawei, full stop. What appears to be more important is a notional 5G future of smart cities and cars that the politicians do not appear to understand yet. A world that they are convinced that the Chinese must not have the ability to either turn off or abuse. Here is Henning Schuldrenk, the former chief technology officer for the US’s Federal Communications Commission again.

Speaker C: It has become symbolic for, in the US and I think to some extent in Europe, where clearly also the aspects of national champions like Ericsson and Nokia and Alcatel as French component of Nokia are relevant. There is a concern that this is becoming one more area where China will essentially take over a high-tech area that will likely at least remain relevant for quite a number of years. So I think that’s it. In that sense, it is more symbolic, as in this just happens to be a highly visible area. And this is largely, again, because of a concern, because 5G has become such an all-purpose buzzword that has an almost assumed magical potion proportions, as in, come on, if you want to be a politician and seem like you know, talk about technology, you mutter something about 5G. If you’re industry, it’s in your interest, industry telecom industry carriers and so on to make 5G seem like some kind of miracle drug for whatever, mind, that you want, education, industrial competitiveness, traffic, autonomous vehicle, security, you name it. You can make at least a plausible case that it is related to that. And so it has, because it’s at the end, because allegations, at least, and Chinese IP theft, and the issues of privacy and security, they’re almost perfectly intersecting in this one company. So you have generalized concerns about European and US competitiveness in high tech. You have 5G, you have privacy security, you have big power rivalry. It’s probably hard to think of a company that is more of an intersection of all of these things at once. And so, that I think partially explains why regardless of what the individual motives of a policymaker is or a politician, which may well be one of the things that you mentioned, they all get to pile on, so to say, on that. And then again, I may sound like I’m sympathetic to Huawei. I don’t I have my own concerns there. I just want to be realistic about what— why this is happening and why now, so to say.

Speaker B: So is 5G just political posturing? High-level sources in Huawei’s competitors have admitted to us that much of the technology needed for smart cities does not need 5G. Indeed, some of the functionality needed for our technological future could even come from the primitive 2G network. The push for 5G would appear to come from the mobile operators, desperate to keep on making more and more future-capable mobile handsets attached to lucrative mobile data contracts. And for the mobile operators, 5G offers yet another attractive and lucrative market: mobile services. These can be sold to the politicians and governments with its ready resonance in the public consciousness of all that the future holds, even though those services could be delivered over existing networks. Here’s Maury Rumney, one of the world’s leading experts on telecoms infrastructure.

Speaker J: Well, I mean, that’s certainly how some of the marketing has been written to play into that sort of high-end latest thing. There is a general evolution in all technology over time. When you see it with, you know, the car manufacturers, they’ll come out with next year’s model in October. They’re trying to buy, they’re trying to get you to buy into the next thing. And it’s the same with telecoms, except in telecoms the next thing tends to come once every 10 years, not every year. Although sometimes we get upgrades, significant upgrades in between. So it’s been 10 years since 4G first came on the scene, and that was certainly a significant step up from what we had with 3G. But with 5G, it’s less clear that the benefits are going to be things that people are going to notice. And the reason for that is largely it’s that the industry needs to generate new income streams, and particularly the vendors. So a lot of the push towards this latest generation has been vendor-led, where they are looking to take the latest advances in technology and package them into something which has a name, in this case 5G. There isn’t a huge difference technically between 4G and 5G, certainly at the radio level. It’s very much an evolution of what we already have, but the way it’s been packaged in this 5G format is primarily a marketing tool to get people’s attention and to drive them to, you know, to take on something new. Now whether the services that are on offer in the shorter term are going to be sufficient to generate the demand that’s needed to pay for all this, that’s very much unclear at this point.

Speaker B: Okay, so what you seem to be saying is that we don’t really need 5G, but I thought that one of the reasons that we needed 5G was for our new automated cars, for our new connected world, for our new smart cities.

Speaker J: Well, let’s take those one at a time. The connected car, I mean, this is an interesting one. People talk about the holy grail of motoring, which is the autonomous car, the one that you can dial up and it will come to where you are and take you to where you want to go and you don’t need to do anything. And the key to that technology is the word autonomous because if something is autonomous, it’s not relying on anything else. In particular, it’s not relying on the cellular network. So the Holy Grail of automation, which is this autonomous vehicle that can drive you anywhere, is not reliant on cellular wireless technology. Certainly not on 5G. And the reason is that wireless networks, cellular networks, are not ubiquitous. You can go to places where they don’t exist, or you can have issues with coverage, you can have dropouts, you can have capacity problems. And there’s no way that you can hand over the critical task of driving a car on the back of a wireless network which doesn’t have the reliability required for such a task.. So the things that are enabling the evolution in cars are local wireless technologies like 77 GHz millimeter wave radar and optical sensors that can read the road and locally make decisions on what needs to be done in a very short space of time. So that’s what’s enabling the, the current automotive industry innovations, and there’s some really good stuff going on there.. But you can augment the navigational aspects and safety aspects of some of this technology with additional features which are delivered by the cellular network. And there is indeed a lot of work going on in standards right now to add vehicular connectivity into the standards. And that’s happening right now. It’s been happening with 4G LTE for a while, and it’s also now happening with, with 5G. And there’s a lot of work to develop new technologies, for instance a sidelink, which is the ability of one car to communicate with another, and also with roadside services so that you can build up a network of auxiliary features which enable you to have a better driving experience. Things like pedestrian collision avoidance or warning of a problem at a traffic junction if somebody’s, you know, skipped hit a red light or something. There are things that could be done if you had low latency communications between vehicles. But those are in addition to the basics of autonomous driving, which I think is what people tend to think about when they talk about 5G and cars.

Speaker B: So what you’re saying is that there’s— to actually achieve that reliability and in fact that vital connectivity for cars, You’ve got to have a range of different devices or different technologies that allow the car to connect, because otherwise it would be unsafe.

Speaker J: Well, I wouldn’t even use the word connect. I think the technologies that are essential for autonomous driving are not connected to anything else, because if they were, if that connection failed, you would no longer have a reliable system. So, so the primary sensors on cars are radar based on millimeter wave, 77 GHz I think is the frequency they use, and those are used for sensing what’s around about the car, and also optical sensors are used for reading road signs and such like. So those are the primary technologies that are used, and those are independent, autonomous from everything else. And to that you can add other features for a whole range of other possibilities in driving. But the basics have to be done using, using technology that’s not connected or not relying on any network services.

Speaker B: Another point that Schultz-Rintz made to us was that the 5G code and technology was still in an early stage, a point echoed by Mike Thierlander, the managing director of the signals research group Thinktank, which tracks the process of 5G across the world.

Speaker G: Well, to put things in perspective, the, the 5G standard was just finished last December, at least the initial phase of it. The standards body continued to work on it, on this current release in June, and even today work continues to complete the initial release of 5G. So to say that Huawei is 18 months ahead in terms of their 5G product is like saying you’re running a marathon and you lose by more than 26 miles to the winner. So it’s in a way theoretically impossible to say that Huawei is that far ahead. You know, I think a lot of it is coming, you know, I’ve heard some European operators that will make that claim in large part because they have an installed base of Huawei infrastructure, and it’s in their best interest to remain with the incumbent vendor, you know, in that case, in some, in some cases being Huawei. What, what I would say is that Huawei is definitely a technology leader. I wouldn’t say they are the technology leader, but it’s fair to say that there’s probably many aspects of 5G where Huawei may have an advantage. Now, the counter to that is when you think about 5G, 5G is deployed in a number of different frequency bands. So if you look at the US, you know, AT&T and Verizon are deploying 5G in millimeter wave frequencies, and that’s kind of unheard of compared to the rest of the world where their initial deployments will be in lower frequencies. And so what that means is that especially given that Huawei doesn’t have a presence in the US, they’re actually way behind 5G when it comes to 5G in millimeter wave frequency. So I think to answer your question, you know, there’s I’m sure definitely areas where Huawei may have an advantage over the Ericssons, Nokias, and Samsungs of the world. I know for certain there are areas where they have a clear disadvantage because they just don’t compete in those markets where those flavors of 5G are being deployed.

Speaker B: It is this concern about Huawei and the basic and elementary nature of the code that could hold more dangers for the UK and other countries using the Huawei equipment than fears over data loss or loss of service to a hostile Chinese government, as the MFC Insight Report ordered by BT 18 years ago stressed.

Speaker A: Another cliché which has gained traction is that Huawei never says no to clients. Instead, the phrase “Yes, we have some and we will show you” is more commonly used in order to keep clients satisfied. On the flip side, Huawei often commits to an aggressive delivery schedule that causes the company to ship immature products that sometimes require Huawei engineers to fix multiple technical problems after a delivery is complete. To this end, Huawei has been known to simply put engineers or technicians on site after the sale to deal with patches and problems.

Speaker B: So in a bid to gain commercial advantage, is Huawei still installing products that are under development. According to the recent research by GCHQ, poor Huawei code has been an ongoing issue for over 10 years.

Speaker H: The issues that have been raised by the Huawei Cybersecurity Evaluation Center, which is basically part of GCHQ but is funded by Huawei, is that there are just— there’s two main issues. The first is that the code is just not particularly well engineered.— and this has been pointed out in various reports from HCSEC, this evaluation center, you know, staffed by people who know what they’re looking at and have come to the conclusion it’s just not very well made. And obviously, if things aren’t very well made, it suggests a certain lack of effort or finesse on Huawei’s part, and potentially that there are vulnerabilities that might be exploited, although that’s not what the evaluation center is actually saying. The second is that The code that’s been supplied to the evaluation center is not the same code that’s being deployed in Huawei kit. The, uh, the binaries, as they call— so the total code sets that have been compared side to side are just simply not the same. So they’re wondering what the reasons for that are. Now, HCSEC is not saying that that’s for any sort of nefarious reasons. It may just be sloppy engineering, or maybe the fact that they haven’t been supplied with the most recent code. But it does raise questions, if you like, about how Huawei is approaching and the deployment of these types of hardware and software on the networks, if they can’t get the engineering right, and if the code sets that are being employed are different to the ones that are being supplied for evaluation. So that’s really the main issue there. The issue that comes out of that, of course, is that when Huawei has been notified of these issues, they’ve been very, very slow in responding to them. And in fact, in many cases, have not responded at all. Which again raises questions about how seriously Huawei are taking this mutual evaluation process they’re undertaking with the UK government.

Speaker B: I mean, it is worrying, isn’t it? Because, you know, these concerns have been raised to Huawei for over 10 years, and even BT at the time that it was managing Huawei was saying to Huawei it was concerned about the code.

Speaker H: Yes, and I think this is part of the frustration that the UK government and the intelligence agencies have with Huawei. You know, we’ve said, we’ve put this process in place to enable Huawei to meet the standards that are expected of a major infrastructure provider in the UK. And part of that has to be a feedback mechanism that Huawei respects, responds to, and actually puts in place measures to mitigate those perceived shortfalls or shortcomings in their products. And the government view through HCSEC and ultimately through the national security apparatus has been that Huawei is not, if you like, like keeping its side of the bargain.

Speaker B: I mean, and this is actually— is quite worrying. There was a report that BT paid for back in 2002, um, from a company called MFC Insight. One of the points that MFC Insight made to BT as part of BT’s due diligence about having Huawei in the network. It says another cliché which has gained traction is that Huawei never says no to clients. Instead, the phrase, yes, we have some and we will show you, is more commonly used in order to keep clients satisfied. And, you know, that as a result of that, they ship immature products. That, that seems to be what they have done. But 10 years is a quite a long time.

Speaker H: Yeah, and this is a common feature of the market, in fact, where security, potential security vulnerabilities and problems are, if you like, shipped with the product before those products have been fully and properly evaluated. And this happens across the board. If this were not the case, two things would happen. The first is that no products would ever get to market. But should you manage to iron out the deficiencies in hardware and software, we wouldn’t have any of these problems in the first place because there’d be no vulnerabilities to exploit. But neither of those situations is, is going to transpire because the products have to go out imperfect. I guess the question here is, is a question of degree. So to what degree do major infrastructure vendors actually test their kits and, and also allow independent auditing of their kit before they go out to market? The answer seems to be in Huawei’s case that it’s more of a rush to get to market and deployment than it is to actually do sufficient initial testing.

Speaker B: But then that becomes a security issue, doesn’t it? It’s a little like saying, right, let’s get the car out there. We know the brakes don’t work, but we’ll make those work later.

Speaker H: Yeah, and this is the sort of analogy that’s used quite often. The difference with a car, even with today’s computerized cars, which are effectively computers with a car on rather than a car with computers in, is that there are still far fewer moving parts than there are for something like a 5G network. It’s almost impossible to rule out the fact that even a well-tested, well-engineered piece of hardware and software doesn’t have vulnerabilities. And it is a security issue because those vulnerabilities get exposed through subsequent research, so post-deployment, once they’ve reached market.

Speaker B: And some of those can be quite serious security issues. Well, that sort of suggests that we shouldn’t really have something like a 5G network up and running if we’re all going to be dependent on it if we can’t rely on it?

Speaker H: Well, you might be able to rely on it most of the time, and I think a lot of the computer security industry relies on the fact that it’s the other bit of the time that is unreliable. So they exist to plug and to fix the problems in other people’s merchandise, and it is a security issue. But you do want a 5G network that does that is relatively reliable and does most of what you want it to do all the time? Or do you want no 5G network at all?

Speaker B: Or a 5G network that a competitive nation could hack into and turn off the network if it wants to. And it may not even be China.

Speaker H: It may be somebody else. It may well be. But we rely on those vulnerabilities as well. And there’s a whole process of what we do with vulnerabilities when we discover them. Do we disclose them to the vendors so that they can patch their products and prove everyone cybersecurity, or do we keep them to ourselves because we might be able to use them for future operations? And this is an issue, what’s called vulnerability equities, and it’s a very live policy issue.

Speaker B: It is this area of poor code that presents more risks to the UK in the future world than the phantoms raised by the US and MI5. Because as a US whistleblower Edward Snowden proved in his revelations about the hacking activity activities of the US. Poor code means that it can be exploited by anyone—nation-state hackers, industrial espionage hackers, or criminal hackers. Poor code in the Huawei network can be exploited not just by the Chinese and the Russians, but by the North Koreans, the Iranians, and even by our own allies. So The recent announcement by the government that it would require security to be built into new Internet of Things devices to make them secure is doubly ironic when it would appear that relying on Huawei in our infrastructure could lay us open to the risks the government thinks it is protecting the public from. That’s all from this edition of Password with me, Peter Warren. The producer was Blue Buffery, and Peter Warren wrote the script. We’ll be back next month with the next episode, and you can watch the Huawei story unfold at our website, Future Intelligence.

Speaker J: Thanks for listening. Goodbye.

Speaker A: This program has been brought to you by Resonance 104.4 FM.

Speaker B: If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00